Description: An issue in the urllib.parse component of Python before v3.11 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters. Broken commit info: Bugfix commit info: https://github.com/python/cpython/pull/99421 https://github.com/python/cpython/pull/99421 https://github.com/python/cpython/pull/99421 https://github.com/python/cpython/pull/99421 https://github.com/python/cpython/pull/99446 (backport for 3.11 branch)